Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-1933

Опубликовано: 17 апр. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1

Описание

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

РелизСтатусПримечание
devel

released

2.3.0-1ubuntu3
lucid

DNE

precise

DNE

quantal

DNE

saucy

DNE

upstream

needed

Показывать по

РелизСтатусПримечание
devel

DNE

lucid

released

1.1.7-1ubuntu0.2
precise

released

1.1.7-4ubuntu0.12.04.1
quantal

released

1.1.7-4ubuntu0.12.10.1
saucy

released

1.1.7+2.0.0-1ubuntu1.1
upstream

needed

Показывать по

EPSS

Процентиль: 30%
0.00111
Низкий

2.1 Low

CVSS2

Связанные уязвимости

redhat
около 12 лет назад

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

nvd
почти 12 лет назад

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

debian
почти 12 лет назад

The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python ...

CVSS3: 4
github
больше 5 лет назад

Pillow Temporary file name leakage

EPSS

Процентиль: 30%
0.00111
Низкий

2.1 Low

CVSS2